10 ms·
You need to add multiple passkeys so if one breaks, you can still access the service. Ditto for Yubikeys (which can be added as a passkey), you need more than
by decryption 3y ago
You need to add multiple passkeys so if one breaks, you can still access the service.
Ditto for Yubikeys (which can be added as a passkey), you need more than one so if you lose it you can still access.
- zoomTo125 3y agoWhat happens if some websites don't allow you to add more than one passkey? Now, you need to keep track of which site has backup key, and which site doesn't have one. Also, the website needs to store multiple public keys now.
- gabeio 3y ago> What happens if some websites don't allow you to add more than one passkey? Do you know of any which currently only allow one passkey?
- woodruffw 3y agoI don't know about Passkeys specifically, but this is unfortunately common enough with WebAuthn rollouts. I'm not sure if it's true anymore, but Twitter for years only supported a single WebAuthn token.
- dinvlad 3y agoI think even Amazon does that too still, such a shame
- JimDabell 3y agoIf you’re referring to AWS, they added support for multiple MFA devices last year: https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/ https://aws.amazon.com/blogs/security/you-can-now-assign-mul... Amazon’s shopping site also lets you set up multiple devices, but I’m not sure when they added that.
- drdaeman 3y agoNo Webauthn support at Amazon.com whatsoever. It's mandatory SMS (you must provide a number and you can't say "I don't want this to be even a backup option") with optional TOTP.
- freitasm 3y agoTailscale only allows one passkey it seems.
- rebeccaskinner 3y agoI see a lot of claims that passkeys are more secure than passwords with 2fa, but my understanding is that they are strictly less secure. As it stands right now, if someone wanted to compromise a service that I use 2fa with, they'd need to both obtain my physical device, and also get my password. Either one of those things may be relatively easy, but it's harder to do both- especially without my knowledge. With passkeys, if someone steals my physical device, then they have full access. That seems strictly worse to me. It's just beyond me how there's a plausible claim that moving to a single factor is better than two factor authentication, except that it gives Google and Apple more control over the internet by allowing them to lock people even more heavily into proprietary OS ecosystems.
- mceachen 3y agoIn my testing, access to your passkey requires your _unlocked_ device (as opposed to a yubikey, which has no on-device authentication)
- als0 3y agoPhysical devices, like Yubikeys and iPhones, have rate limited PINs. It’s not enough just to steal a device.
- aniforprez 3y ago> With passkeys, if someone steals my physical device, then they have full access Unless they also have access to your fingerprints, face or something to that effect, they do not have access to your device. Every time I create a passkey, I am required by the device to provide authentication. I'm not sure if this is a hard requirement because all my devices have PINs, passwords and fingerprints but I assume that your device needs to have some form of security for passkeys to even work. In 1Password's demo, I had to authorise every individual login call with my system PIN on Windows and fingerprint on Android If you don't use biometrics and use a pin/password and the attacker has access to both your device and this information, then there is no difference to how it currently operates because the attacker already has all the info necessary to take over your accounts. If an attacker has your device AND access to biometrics, then you have bigger problems
- drdaeman 3y agoWhich is going to be a major pain in the ass. Every time you sign up for something you have to perform a complex rite: 1) sign up or add a portable authenticator (Yubikey or software token in something cross-platform like 1Password); and 2) run around the house, grabbing up all the different devices you have that aren't transparently synchronizing (so, something from Apple, something from Microsoft, something from Google, and don't forget that backup Yubikey you have in a safe too) and enrolling them on the same website. I'm baffled how this obvious issue is not just unsolved at the start, but is not even addressed by any user-facing marketing materials. Every single demo stops at enrolling one single device, period. The word is that vendors will do you good magically letting you access that passkey from everywhere - and they missed that huge fucking asterisk after "everywhere". Because they won't - Google, Apple, Microsoft, 1Password, and probably everyone else have no incentive to do so, they want to stay in their respective ecosystems and no chance in hell they're doing any cross-platform interop with anything that not theirs. Apple, Google and Microsoft would love this model. People suddenly swayed to stay within their ecosystem to log in to websites. "Oh shit can't login from here, gotta start Microsoft Edge to access this website" sounds exactly like what those corporations fancy. Yubico and 1Password don't have a beef with it - someone wants a portable authenticator, they're gonna pay for it - it's not like there are many options anyway. And only me - as an end user - is not exactly happy. Even though I do want to get rid of passwords and replace them with keypairs. --- Add: This said, if you're at some conference attending a talk about Passkeys... Please consider raising this point and explicitly not letting it slide with the usual waiver of "nothing to worry about, $VendorName will sync the Passkeys across your devices". Raising awareness is important.
- stavros 3y agoI don't understand the issue here. Passkeys are just a way for a site to ask your browser for credentials. If you don't like the current solutions, write your own, and it'll work with all Passkeys-enabled sites. Why do you need the standard to be different?
- JohnFen 3y agoWriting your own is only an option as long as everyone ignores attestation. Which might be what everyone does -- but the standard absolutely supports attestation, so there's no guarantee.
- n42 3y agono, this is false. this is different than 2FA. you can reset your passkey just like you can a password.
- freitasm 3y agoYou can if there is a provision for that. As mentioned before it doesn't look like Taiscale allows you to either have more than one passkey or reset the passkey.
- n42 3y agohm. I guess these are the early days for the industry where providers are figuring this stuff out. I won't be surprised to see them add that. yes, you can lose keys, even (especially) if they are digital!
- freitasm 3y agoExcept the Tailscale implementation doesn't allow you to add more passkeys to an account. There is no "one account multiple keys" here.